LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-45830

trychroma · chromadb

Published
CVSS8.8
Severityhigh
WeaknessCWE-639
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-45830

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-45830.